Skip to main content

RuPay BEPG


When you request an authorization using a supported card type and a supported processor, you can include payer authentication data in the request.

There are two versions of RuPay available for Bharat Ecommerce Payment Gateway (BEPG):

  • Redirection flow: the customer is redirected from the merchant to an authentication page hosted by the issuer.

  • Seamless flow: the customer goes to an authentication page hosted on your website (merchant). You can use either a token or an account number in an authorization request.

    For seamless flow, your system must be Payment Card Industry Data Security Standard (PCI DSS) compliant. You might have to use a token to ensure PCI DSS compliance.

Before implementing payer authentication, contact customer support to have your account configured for this feature.

Supported Processor

  • RuPay

Endpoints

POST /pts/v2/payments

POST /pts/v2/payments

POST /pts/v2/payments

Fields Specific to the Bharat Ecommerce Payment Gateway Use Case

orderInformation.amountDetails.currency Required

Set the value to INR.

Authorizations Using Redirection Flow

Redirection flow authenticates the customer by directing the customer from the merchant site to an authentication page that is hosted by the issuer.

Example

{    "clientReferenceInformation": {        "code": "12345678"    },    "consumerAuthenticationInformation": {        "cavv": "MTAM123M456M789",        "xid": "1234567890"    },    "processingInformation": {        "commerceIndicator": "rpy"    },    "orderInformation": {        "billTo": {            "country": "US",            "lastName": "Doe",            "address2": "Unit 123456",            "address1": "12345 Main Street",            "postalCode": "48104-2201",            "locality": "Ann Arbor",            "administrativeArea": "MI",            "firstName": "John",            "phoneNumber": "999999999",            "district": "MI",            "buildingNumber": "123",            "company": "Visa",            "email": "[email protected]"        },        "amountDetails": {            "totalAmount": "12456.00",            "currency": "INR"        }    },    "paymentInformation": {        "card": {            "expirationYear": "2031",            "number": "41111111XXXXXXX1",            "securityCode": "123",            "expirationMonth": "12",            "type": "061"        }    }}
{    "_links": {        "authReversal": {            "method": "POST",            "href": "/pts/v2/payments/6443452051237111442758/reversals"        },        "self": {            "method": "GET",            "href": "/pts/v2/payments/6443452051237111442758"        },        "capture": {            "method": "POST",            "href": "/pts/v2/payments/6443452051237111442758/captures"        }    },    "clientReferenceInformation": {        "code": "TC50171_3"    },    "id": "6443452051237111442758",    "orderInformation": {        "amountDetails": {            "authorizedAmount": "12456.00",            "currency": "INR"        }    },    "paymentAccountInformation": {        "card": {            "brandName": "RUPAY",            "type": "061"        }    },    "paymentInformation": {        "tokenizedCard": {            "type": "061"        },        "card": {            "type": "061"        }    },    "processorInformation": {        "approvalCode": "183217",        "networkTransactionId": "100000000000000000000000025253",        "transactionId": "100000000000000000000000025253",        "responseCode": "00",        "avs": {            "code": "2"        }    },    "status": "AUTHORIZED",    "submitTimeUtc": "2022-02-08T18:33:30Z"}

Required Fields

These fields are required when you use an account number in an authorization request for seamless flow. The values for these fields are in the response from the payer authentication validate service. When you request the payer authentication validate and authorization services together, the data is automatically passed from one service to the other.

FieldDescription
aggregatorInformation.aggregatorIdRequired for an aggregator or seller. Otherwise, this field is optional.
aggregatorInformation.submerchant.merchantIdRequired for an aggregator or seller only when aggregatorInformation.aggregatorId is not present in the response from the payer authentication validate service. Otherwise, this field is optional.
aggregatorInformation.submerchant.nameRequired for an aggregator or seller. Otherwise, this field is optional.
clientReferenceInformation.codeOrder reference or tracking number. Provide a unique value for each transaction so that you can perform meaningful searches for the transaction.
deviceInformation.httpAcceptBrowserValue—
deviceInformation.ipAddress—
deviceInformation.userAgentBrowserValue—
orderInformation.amountDetails.totalAmount—
orderInformation.amountDetails.currencySet the value to INR.
orderInformation.billTo.address1—
orderInformation.billTo.administrativeArea—
orderInformation.billTo.country—
orderInformation.billTo.email—
orderInformation.billTo.firstName—
orderInformation.billTo.lastName—
orderInformation.billTo.locality—
orderInformation.billTo.postalCode—
payerAuthentication.authenticationValue—
paymentInformation.card.expirationMonth—
paymentInformation.card.expirationYear—
paymentInformation.card.securityCode—
paymentInformation.card.number—
processingInformation.commerceIndicatorSet the value to rpy.

Optional Fields

You can use these optional fields to include additional information when processing an authorization using the redirection flow method.

Optional Fields
FieldDescription
merchantInformation.categoryCode—
merchantInformation.merchantDescriptor.contact—
merchantInformation.merchantDescriptor.locality—
merchantInformation.merchantDescriptor.name—
merchantInformation.merchantDescriptor.postalCode—
merchantInformation.transactionLocalDateTimeIf you do not send this field, the system time in Indian Standard Time (IST) is used.

Authorizations Using Seamless Flow with an Account Number (No Token)

Seamless flow authenticates the customer during an online purchase and protects payment information with a one-time password that is hosted on your website. This section explains how to authorize Seamless Flow transactions using an account number in the authorization request.

Example

{    "clientReferenceInformation": {        "code": "RTS-Auth"    },    "processingInformation": {        "commerceIndicator": "rpy",        "capture":"true"    },    "orderInformation": {        "billTo": {            "country": "IN",            "lastName": "Doe",            "firstName": "John",            "address2": "test",            "address1": "12345 Main St.",            "locality": "48104 2201",            "administrativeArea": "TN",            "phoneNumber": "999999999",            "postalCode": "411040",            "district": "MI",            "buildingNumber": "123",            "company": "Visa",            "email": "[email protected]"        },        "amountDetails": {            "totalAmount": "100.00",            "currency": "inr"        }    },    "paymentInformation": {        "card": {            "expirationYear": "2031",            "number": "41111111XXXXXXX1",            "securityCode": "123",            "securityCodeIndicator": "1",            "expirationMonth": "12",            "type": "061"        }    },    "deviceInformation": {        "httpAcceptBrowserValue": "123456",        "ipAddress": "10.10.10.10",        "userAgentBrowserValue": "aa"    },    "aggregatorInformation": {        "subMerchant": {            "name": "rupay"        }    },     "merchantInformation": {        "merchantDescriptor": {            "administrativeArea": "AN",            "postalCode": "123324",            "transactionLocalDateTime":"19255610122021",            "contact":"23423423423"        }    },    "consumerAuthenticationInformation": {        "transactionToken": "MTAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDI1MjM2"    }}
{    "_links": {        "authReversal": {            "method": "POST",            "href": "/pts/v2/payments/6385272861347128228688/reversals"        },        "self": {            "method": "GET",            "href": "/pts/v2/payments/6385272861347128228688"        },        "capture": {            "method": "POST",            "href": "/pts/v2/payments/6385272861347128228688/captures"        }    },    "clientReferenceInformation": {        "code": "RTS-Auth"    },    "id": "63852728665346435458228688",    "orderInformation": {        "amountDetails": {            "authorizedAmount": "100.00",            "currency": "inr"        }    },    "paymentAccountInformation": {        "card": {            "brandName": "RUPAY",            "type": "061"        }    },    "paymentInformation": {        "tokenizedCard": {            "type": "061"        },        "card": {            "type": "061"        }    },    "processorInformation": {        "approvalCode": "123456",        "networkTransactionId": "100000000000000000000000025253",        "transactionId": "100000000000000000000000025253",        "responseCode": "00",        "avs": {            "code": "2"        }    },    "status": "AUTHORIZED",    "submitTimeUtc": "2021-12-03T10:28:06Z"}

Required Fields

These fields are required when you use an account number in an authorization request for seamless flow. The values for these fields are in the response from the payer authentication validate service. When you request the payer authentication validate and authorization services together, the data is automatically passed from one service to the other.

FieldDescription
aggregatorInformation.aggregatorIdRequired for an aggregator or seller. Otherwise, this field is optional.
aggregatorInformation.submerchant.merchantIdRequired for an aggregator or seller only when aggregatorInformation.aggregatorId is not present in the response from the payer authentication validate service. Otherwise, this field is optional.
aggregatorInformation.submerchant.nameRequired for an aggregator or seller. Otherwise, this field is optional.
clientReferenceInformation.codeOrder reference or tracking number. Provide a unique value for each transaction so that you can perform meaningful searches for the transaction.
deviceInformation.httpAcceptBrowserValue—
deviceInformation.ipAddress—
deviceInformation.userAgentBrowserValue—
orderInformation.amountDetails.totalAmount—
orderInformation.amountDetails.currencySet the value to INR.
orderInformation.billTo.address1—
orderInformation.billTo.administrativeArea—
orderInformation.billTo.country—
orderInformation.billTo.email—
orderInformation.billTo.firstName—
orderInformation.billTo.lastName—
orderInformation.billTo.locality—
orderInformation.billTo.postalCode—
payerAuthentication.authenticationValue—
paymentInformation.card.expirationMonth—
paymentInformation.card.expirationYear—
paymentInformation.card.securityCode—
paymentInformation.card.number—
processingInformation.commerceIndicatorSet the value to rpy.

Optional Fields

You can use these optional fields to include additional information when processing an authorization using the seamless flow with an account number (no token) method.

Optional Fields
FieldDescription
merchantInformation.categoryCode—
merchantInformation.merchantDescriptor.contact—
merchantInformation.merchantDescriptor.locality—
merchantInformation.merchantDescriptor.name—
merchantInformation.merchantDescriptor.postalCode—
merchantInformation.transactionLocalDateTimeIf you do not send this field, the system time in Indian Standard Time (IST) is used.

Authorizations Using Seamless Flow with a Token

Seamless flow authenticates the customer during an online purchase and protects payment information using a one-time password that is hosted on your website. This section explains how to authorize seamless flow transactions using a token in the authorization request.

Example

{    "clientReferenceInformation": {        "code": "RTS-Auth"    },    "processingInformation": {        "commerceIndicator": "rpy"    },    "orderInformation": {        "billTo": {            "country": "US",            "lastName": "Doe",            "address2": "Apt. 2",            "address1": "123456 Main St.",            "postalCode": "560066",            "locality": "94043",            "administrativeArea": "CA",            "firstName": "John",            "phoneNumber": "999999999",            "district": "MI",            "buildingNumber": "123",            "company": "Visa",            "email": "[email protected]"        },        "amountDetails": {            "totalAmount": "100.00",            "currency": "inr"        }    },    "paymentInformation": {        "tokenizedCard": {            "number": "41111111XXXXXXX1",            "transactionType": "1",            "expirationYear": "2031",            "securityCode": "123",            "securityCodeIndicator": "1",            "expirationMonth": "12",            "cryptogram": "abcdefgh"        }    },    "consumerAuthenticationInformation": {        "transactionToken": "MTAwMDAwM1234567890",        "authenticationTransactionContextId": "123456789012345678901234567890"    },    "deviceInformation": {        "ipAddress": "10.10.10.10",        "httpAcceptBrowserValue": "text/html",        "userAgentBrowserValue" : "Mozilla/5.0 (compatible; MSIE 9.0; Windows Phone OS 7.5; Trident/5.0; IEMobile/9.0)"    },    "aggregatorInformation": {        "subMerchant": {            "name": "rupay"        }    },    "merchantInformation": {        "merchantDescriptor": {            "administrativeArea": "AN",            "postalCode": "123324",            "transactionLocalDateTime":"19255610122021",            "contact":"23423423423"        }    }}
{    "_links": {        "authReversal": {            "method": "POST",            "href": "/pts/v2/payments/6383780039607106528664/reversals"        },        "self": {            "method": "GET",            "href": "/pts/v2/payments/6383780039607106528664"        },        "capture": {            "method": "POST",            "href": "/pts/v2/payments/6383780039607106528664/captures"        }    },    "clientReferenceInformation": {        "code": "RTS-Auth"    },    "id": "6383780039607106528664",    "orderInformation": {        "amountDetails": {            "authorizedAmount": "100.00",            "currency": "inr"        }    },    "paymentAccountInformation": {        "card": {            "brandName": "RUPAY",            "type": "061"        }    },    "paymentInformation": {        "tokenizedCard": {            "type": "061"        },        "card": {            "type": "061"        }    },    "processorInformation": {        "approvalCode": "235426",        "networkTransactionId": "100000000000000000000000025253",        "transactionId": "100000000000000000000000025253",        "responseCode": "00",        "avs": {            "code": "2"        }    },    "status": "AUTHORIZED",    "submitTimeUtc": "2021-12-01T17:00:04Z"}

Required Fields

These fields are required when you use a token in an authorization request for Seamless Flow. The values for these fields are in the response from the payer authentication validate service. When you request the payer authentication validate and authorization services together, the data is automatically passed from one service to the other.

FieldDescription
aggregatorInformation.aggregatorIdRequired for an aggregator or seller. Otherwise, this field is optional.
aggregatorInformation.subMerchant.idRequired for an aggregator or seller when aggregatorInformation.aggregatorId is not present in the response from the payer authentication validate service. Otherwise, this field is optional.
aggregatorInformation.submerchant.nameRequired for an aggregator or seller. Otherwise, this field is optional.
clientReferenceInformation.codeOrder reference or tracking number. Provide a unique value for each transaction so that you can perform meaningful searches for the transaction.
consumerAuthenticationInformation.authenticationTransactionContextId—
consumerAuthenticationInformation.transactionTokenSet the value to the token sent by RuPay. The response from the payer authentication validate service contains the token.
deviceInformation.httpAcceptBrowserValue—
deviceInformation.ipAddress—
deviceInformation.userAgentBrowserValue—
merchantInformation.transactionLocalDateTime—
orderInformation.amountDetails.totalAmount—
orderInformation.amountDetails.currencySet the value to INR.
orderInformation.billTo.address1—
orderInformation.billTo.administrativeArea—
orderInformation.billTo.country—
orderInformation.billTo.email—
orderInformation.billTo.firstName—
orderInformation.billTo.lastName—
orderInformation.billTo.locality—
orderInformation.billTo.postalCode—
paymentInformation.tokenizedCard.cryptogram—
paymentInformation.tokenizedCard.expirationMonth—
paymentInformation.tokenizedCard.expirationYear—
paymentInformation.tokenizedCard.number—
paymentInformation.tokenizedCard.securityCode—
paymentInformation.tokenizedCard.transactionTypeSet the value to 1.
processingInformation.commerceIndicatorSet the value to rpy.

Last published: September 29, 2026